CVE Database

CVE-2022-30601CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-522

Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable information disclosure and escalation of privilege via network access.

CVE-2022-36947CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Unsafe Parsing of a PNG tRNS chunk in FastStone Image Viewer through 7.5 results in a stack buffer overflow.

CVE-2020-36599CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-116

lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.

CVE-2022-35540CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access.

CVE-2022-29805CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code via a crafted XML payload.

CVE-2022-36220CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Kiosk breakout (without quit password) in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code execution via the browsers' print dialog.

CVE-2022-34615CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-521

Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks.

CVE-2022-36605CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter.

CVE-2022-36606CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Ywoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database.

CVE-2022-36578CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

jizhicms v2.3.1 has SQL injection in the background.

CVE-2022-23459CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx use of the Value class may lead to memory corruption via a double free or via a use after free. The value class has a default assignment operator which may be used with pointer types which may point to alterable data where the pointer itself is not updated. This issue exists on the current commit of the jsonxx project. The project itself has been archived and updates are not expected. Users are advised to find a replacement.

CVE-2022-37175CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet.

CVE-2022-36030CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack of sensitization of user input. This issue has not yet been patched. Users are advised to restrict user input and to upgrade when a new release becomes available.

CVE-2022-34916CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.

CVE-2022-36198CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin/pass-bwdates-reports-details.php, buspassms/admin/changeimage.php, buspassms/admin/search-pass.php, buspassms/admin/edit-category-detail.php, and buspassms/admin/edit-pass-detail.php

CVE-2022-2927CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-521

Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7.

CVE-2020-27836CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-732

A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability..

CVE-2021-3586CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1188

A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allowing access to all ports on these resources from any pod. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2022-34149CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-264

Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.

CVE-2022-34773CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

Tabit - HTTP Method manipulation. https://bridge.tabit.cloud/configuration/addresses-query - can be POST-ed to add addresses to the DB. This is an example of OWASP:API8 – Injection.

CVE-2022-34858CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.

CVE-2022-37134CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1284

D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be decrypted by base64, and the result will be stored in v94, which does not check the size of l2tp_usrname, resulting in stack overflow.

CVE-2022-35150CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.

CVE-2022-2842CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability classified as critical has been found in SourceCodester Gym Management System. This affects an unknown part of the file login.php. The manipulation of the argument user_email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-206451.

CVE-2022-37800CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function fromSetRouteStatic.

CVE-2022-38667CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

HTTP applications (servers) based on Crow through 1.0+4 may allow a Use-After-Free and code execution when HTTP pipelining is used. The HTTP parser supports HTTP pipelining, but the asynchronous Connection layer is unaware of HTTP pipelining. Specifically, the Connection layer is unaware that it has begun processing a later request before it has finished processing an earlier request.

CVE-2021-42232CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command. This will cause an attacker to execute arbitrary commands on the router.

CVE-2022-34919CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authenticated. By uploading a crafted aspx file, it is possible to execute arbitrary commands.

CVE-2021-42627CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.

CVE-2022-37199CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.

CVE-2022-37223CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.

CVE-2022-37111CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

BlueCMS 1.6 has SQL injection in line 132 of admin/article.php

CVE-2022-37112CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

BlueCMS 1.6 has SQL injection in line 55 of admin/model.php

CVE-2022-35726CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Broken Authentication vulnerability in yotuwp Video Gallery plugin <= 1.3.4.5 at WordPress.

CVE-2022-37113CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Bluecms 1.6 has SQL injection in line 132 of admin/area.php

CVE-2022-35115CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php.

CVE-2022-38078CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially crafted message by POST method to Movable Type XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be executed through it. Affected products and versions are as follows: Movable Type 7 r.5202 and earlier, Movable Type Advanced 7 r.5202 and earlier, Movable Type 6.8.6 and earlier, Movable Type Advanced 6.8.6 and earlier, Movable Type Premium 1.52 and earlier, and Movable Type Premium Advanced 1.52 and earlier. Note that all versions of Movable Type 4.0 or later including unsupported (End-of-Life, EOL) versions are also affected by this vulnerability.

CVE-2021-39815CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid ID: A-232440670

CVE-2022-20122CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid ID: A-232441339

CVE-2022-37181CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

72crm 9.0 has an Arbitrary file upload vulnerability.

CVE-2022-32839CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A remote user may cause an unexpected app termination or arbitrary code execution.

CVE-2022-34960CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-59

The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations on the host device. This allows the attacker to mount any arbitrary file to any location on the host.

CVE-2022-2957CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability classified as critical was found in SourceCodester Simple and Nice Shopping Cart Script. Affected by this vulnerability is an unknown functionality of the file /mkshop/Men/profile.php. The manipulation of the argument mem_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-207001 was assigned to this vulnerability.

CVE-2022-36672CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session.

CVE-2022-37240CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.

CVE-2022-37242CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.

CVE-2022-37798CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetVirtualSer.

CVE-2022-37799CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter at the function setSmartPowerManagement.

CVE-2022-37158CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-521

RuoYi v3.8.3 has a Weak password vulnerability in the management system.

CVE-2022-37159CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.

← PreviousPage 445 / 7034Next →